Legal

Privacy Policy

Last updated: June 11, 2026

This Privacy Policy describes how SISBRAPAG — Sistema Brasil Pagamentos Digitais Ltda. ("SISBRAPAG", "we", "us", or "our") collects, uses, and protects your personal data in accordance with Brazilian Law No. 13,709/2018 (Lei Geral de Proteção de Dados — LGPD) and applicable regulations.

1. Data We Collect

We collect the following categories of personal data:

2. How We Use Your Data

We use your data to:

3. Legal Basis for Processing

Under the LGPD, we process your data based on: (a) contract performance — to provide the services you requested; (b) legal obligation — to comply with Brazilian financial regulations; (c) legitimate interest — to improve our platform and prevent fraud; (d) consent — where we ask for it explicitly.

4. Data Storage

Your data is stored securely on Supabase infrastructure (hosted on AWS in the sa-east-1 region — São Paulo, Brazil). Documents you upload are stored in encrypted private storage buckets accessible only to you and authorized SISBRAPAG staff.

5. Data Sharing

We do not sell your personal data. We may share it with:

6. Your Rights (LGPD)

Under the LGPD, you have the right to:

To exercise any of these rights, contact us at hello@sisbrapag.com.

7. Data Retention

We retain your personal data for as long as your account is active and for up to 5 years after account closure, as required by Brazilian financial regulations. Transaction records may be retained for up to 10 years for compliance purposes.

8. Cookies and Analytics

Our website collects basic, anonymous page view data (page path, referrer, browser agent) to understand how our site is used. We do not use third-party advertising cookies. No cross-site tracking occurs.

9. Security

We implement industry-standard security measures including encrypted storage, HTTPS-only access, row-level security on our database, and server-side API key management. No system is completely secure, and we encourage you to use a strong email account to protect your magic-link access.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email. The date at the top of this page reflects the most recent revision.

11. Contact & DPO

For privacy-related questions or to exercise your LGPD rights, contact us at:

Terms of Service →